Saturday, July 24, 2010

ISS - History of the Quarantine Rules Event Logs viewing

The current active Quarantine rules can be viewed in Proventia Manager under the Intrusion Prvention>Quarantined Instrusion tab. However , this view does not show the history of the Quarantine Rules. This history of the Quarantine Rules that were used and when they were added can be viewed in cache/ISS/eventxxxx.log file
Using WinSCP Tool , log into ISS Proventia Appliance using root Username ,and Password.
under cache/ISS/eventxxxx.log file we can view the logs
This is the log file that will contain entries when quarantine are added , expired or deleted
(manually removed via the Intrusion Prevention>Quarantine Intrusion tab)